<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 10:59:43 +0000</lastBuildDate>
    <item>
      <title>3ADR011536 — AC500 V3 Stack buffer overflow in Cryptographic Message Syntax</title>
      <link>https://cve.radiocsirt.org/vuln/3adr011536</link>
      <description>&lt;p&gt;ABB became aware of vulnerability in the products versions listed as affected in the advisory. An update is available that resolves publicly reported vulnerability.&lt;/p&gt;
&lt;p&gt;An attacker who successfully exploited these vulnerabilities could cause a crash, denial-of-service (DoS), or potentially remote code execution.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;ABB became aware of vulnerability in the products versions listed as affected in the advisory. An update is available that resolves publicly reported vulnerability.&lt;/p&gt;
&lt;p&gt;An attacker who successfully exploited these vulnerabilities could cause a crash, denial-of-service (DoS), or potentially remote code execution.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/3adr011536</guid>
    </item>
    <item>
      <title>ALSA-2026:1472 — Important: openssl security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2026:1472</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:10: openssl, AlmaLinux:10: openssl-devel, AlmaLinux:10: openssl-libs, AlmaLinux:10: openssl-perl&lt;/p&gt;
&lt;p&gt;OpenSSL is a toolkit that implements the Secure Sockets Layer (SSL) and Transport Layer Security (TLS) protocols, as well as a full-strength general-purpose cryptography library.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* openssl: OpenSSL: Arbitrary code execution or denial of service through crafted PKCS#12 file (CVE-2025-11187)
  * openssl: OpenSSL: Remote code execution or Denial of Service via oversized Initialization Vector in CMS parsing (CVE-2025-15467)
  * openssl: OpenSSL: Denial of Service via NULL pointer dereference in QUIC protocol handling (CVE-2025-15468)
  * openssl: OpenSSL: Data integrity bypass in `openssl dgst` command due to silent truncation (CVE-2025-15469)
  * openssl: OpenSSL: Denial of Service due to excessive memory allocation in TLS 1.3 certificate compression (CVE-2025-66199)
  * openssl: OpenSSL: Denial of Service due to out-of-bounds write in BIO filter (CVE-2025-68160)
  * openssl: OpenSSL: Information disclosure and data tampering via specific low-level OCB encryption/decryption calls (CVE-2025-69418)
  * openssl: OpenSSL: Arbitrary code execution due to out-of-bounds write in PKCS#12 processing (CVE-2025-69419)
  * openssl: OpenSSL: Denial of Service via malformed PKCS#12 file processing (CVE-2025-69421)
  * openssl: OpenSSL: Denial of Service via malformed TimeStamp Response (CVE-2025-69420)
  * openssl: OpenSSL: Denial of Service due to type confusion in PKCS#12 file processing (CVE-2026-22795)
  * openssl: OpenSSL: Denial of Service via type confusion i…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:10: openssl, AlmaLinux:10: openssl-devel, AlmaLinux:10: openssl-libs, AlmaLinux:10: openssl-perl&lt;/p&gt;
&lt;p&gt;OpenSSL is a toolkit that implements the Secure Sockets Layer (SSL) and Transport Layer Security (TLS) protocols, as well as a full-strength general-purpose cryptography library.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* openssl: OpenSSL: Arbitrary code execution or denial of service through crafted PKCS#12 file (CVE-2025-11187)
  * openssl: OpenSSL: Remote code execution or Denial of Service via oversized Initialization Vector in CMS parsing (CVE-2025-15467)
  * openssl: OpenSSL: Denial of Service via NULL pointer dereference in QUIC protocol handling (CVE-2025-15468)
  * openssl: OpenSSL: Data integrity bypass in `openssl dgst` command due to silent truncation (CVE-2025-15469)
  * openssl: OpenSSL: Denial of Service due to excessive memory allocation in TLS 1.3 certificate compression (CVE-2025-66199)
  * openssl: OpenSSL: Denial of Service due to out-of-bounds write in BIO filter (CVE-2025-68160)
  * openssl: OpenSSL: Information disclosure and data tampering via specific low-level OCB encryption/decryption calls (CVE-2025-69418)
  * openssl: OpenSSL: Arbitrary code execution due to out-of-bounds write in PKCS#12 processing (CVE-2025-69419)
  * openssl: OpenSSL: Denial of Service via malformed PKCS#12 file processing (CVE-2025-69421)
  * openssl: OpenSSL: Denial of Service via malformed TimeStamp Response (CVE-2025-69420)
  * openssl: OpenSSL: Denial of Service due to type confusion in PKCS#12 file processing (CVE-2026-22795)
  * openssl: OpenSSL: Denial of Service via type confusion i…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2026:1472</guid>
    </item>
    <item>
      <title>bdu:2026-00890</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2026-00890</link>
      <description>bdu:2026-00890</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2026-00890</guid>
    </item>
    <item>
      <title>BELL-CVE-2025-15467</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2025-15467</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: openssl, Alpaquita:25: openssl, Alpaquita:stream: openssl, BellSoft Hardened Containers:23: openssl, BellSoft Hardened Containers:25: openssl, BellSoft Hardened Containers:stream: openssl&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: openssl, Alpaquita:25: openssl, Alpaquita:stream: openssl, BellSoft Hardened Containers:23: openssl, BellSoft Hardened Containers:25: openssl, BellSoft Hardened Containers:stream: openssl&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2025-15467</guid>
    </item>
    <item>
      <title>certfr-2026-avi-0096 — De multiples vulnérabilités ont été découvertes dans OpenSSL. Certaines d'entre elles permettent à un attaquant de prov…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0096</link>
      <description>certfr-2026-avi-0096</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-0096</guid>
    </item>
    <item>
      <title>Withdrawn: CLEANSTART-2026-GK72927 — Issue summary: PBMAC1 parameters in PKCS#12 files are missing validation
which can trigger a stack-based buffer overflo…</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-gk72927</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: openssl&lt;/p&gt;
&lt;p&gt;Multiple security vulnerabilities affect the openssl package. Issue summary: PBMAC1 parameters in PKCS#12 files are missing validation which can trigger a stack-based buffer overflow, invalid pointer or NULL pointer dereference during MAC verification. See references for individual vulnerability details.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: openssl&lt;/p&gt;
&lt;p&gt;Multiple security vulnerabilities affect the openssl package. Issue summary: PBMAC1 parameters in PKCS#12 files are missing validation which can trigger a stack-based buffer overflow, invalid pointer or NULL pointer dereference during MAC verification. See references for individual vulnerability details.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-gk72927</guid>
    </item>
    <item>
      <title>EUVD-2026-364478</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-364478</link>
      <description>EUVD-2026-364478</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-364478</guid>
    </item>
    <item>
      <title>fkie_cve-2025-15467</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-15467</link>
      <description>&lt;p&gt;Issue summary: Parsing CMS AuthEnvelopedData or EnvelopedData message with
maliciously crafted AEAD parameters can trigger a stack buffer overflow.&lt;/p&gt;
&lt;p&gt;Impact summary: A stack buffer overflow may lead to a crash, causing Denial
of Service, or potentially remote code execution.&lt;/p&gt;
&lt;p&gt;When parsing CMS (Auth)EnvelopedData structures that use AEAD ciphers such as
AES-GCM, the IV (Initialization Vector) encoded in the ASN.1 parameters is
copied into a fixed-size stack buffer without verifying that its length fits
the destination. An attacker can supply a crafted CMS message with an
oversized IV, causing a stack-based out-of-bounds write before any
authentication or tag verification occurs.&lt;/p&gt;
&lt;p&gt;Applications and services that parse untrusted CMS or PKCS#7 content using
AEAD ciphers (e.g., S/MIME (Auth)EnvelopedData with AES-GCM) are vulnerable.
Because the overflow occurs prior to authentication, no valid key material
is required to trigger it. While exploitability to remote code execution
depends on platform and toolchain mitigations, the stack-based write
primitive represents a severe risk.&lt;/p&gt;
&lt;p&gt;The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this
issue, as the CMS implementation is outside the OpenSSL FIPS module
boundary.&lt;/p&gt;
&lt;p&gt;OpenSSL 3.6, 3.5, 3.4, 3.3 and 3.0 are vulnerable to this issue.&lt;/p&gt;
&lt;p&gt;OpenSSL 1.1.1 and 1.0.2 are not affected by this issue.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Issue summary: Parsing CMS AuthEnvelopedData or EnvelopedData message with
maliciously crafted AEAD parameters can trigger a stack buffer overflow.&lt;/p&gt;
&lt;p&gt;Impact summary: A stack buffer overflow may lead to a crash, causing Denial
of Service, or potentially remote code execution.&lt;/p&gt;
&lt;p&gt;When parsing CMS (Auth)EnvelopedData structures that use AEAD ciphers such as
AES-GCM, the IV (Initialization Vector) encoded in the ASN.1 parameters is
copied into a fixed-size stack buffer without verifying that its length fits
the destination. An attacker can supply a crafted CMS message with an
oversized IV, causing a stack-based out-of-bounds write before any
authentication or tag verification occurs.&lt;/p&gt;
&lt;p&gt;Applications and services that parse untrusted CMS or PKCS#7 content using
AEAD ciphers (e.g., S/MIME (Auth)EnvelopedData with AES-GCM) are vulnerable.
Because the overflow occurs prior to authentication, no valid key material
is required to trigger it. While exploitability to remote code execution
depends on platform and toolchain mitigations, the stack-based write
primitive represents a severe risk.&lt;/p&gt;
&lt;p&gt;The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this
issue, as the CMS implementation is outside the OpenSSL FIPS module
boundary.&lt;/p&gt;
&lt;p&gt;OpenSSL 3.6, 3.5, 3.4, 3.3 and 3.0 are vulnerable to this issue.&lt;/p&gt;
&lt;p&gt;OpenSSL 1.1.1 and 1.0.2 are not affected by this issue.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-15467</guid>
    </item>
    <item>
      <title>GHSA-wvhq-3h88-rf6g</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-wvhq-3h88-rf6g</link>
      <description>&lt;p&gt;Issue summary: Parsing CMS AuthEnvelopedData message with maliciously
crafted AEAD parameters can trigger a stack buffer overflow.&lt;/p&gt;
&lt;p&gt;Impact summary: A stack buffer overflow may lead to a crash, causing Denial
of Service, or potentially remote code execution.&lt;/p&gt;
&lt;p&gt;When parsing CMS AuthEnvelopedData structures that use AEAD ciphers such as
AES-GCM, the IV (Initialization Vector) encoded in the ASN.1 parameters is
copied into a fixed-size stack buffer without verifying that its length fits
the destination. An attacker can supply a crafted CMS message with an
oversized IV, causing a stack-based out-of-bounds write before any
authentication or tag verification occurs.&lt;/p&gt;
&lt;p&gt;Applications and services that parse untrusted CMS or PKCS#7 content using
AEAD ciphers (e.g., S/MIME AuthEnvelopedData with AES-GCM) are vulnerable.
Because the overflow occurs prior to authentication, no valid key material
is required to trigger it. While exploitability to remote code execution
depends on platform and toolchain mitigations, the stack-based write
primitive represents a severe risk.&lt;/p&gt;
&lt;p&gt;The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this
issue, as the CMS implementation is outside the OpenSSL FIPS module
boundary.&lt;/p&gt;
&lt;p&gt;OpenSSL 3.6, 3.5, 3.4, 3.3 and 3.0 are vulnerable to this issue.&lt;/p&gt;
&lt;p&gt;OpenSSL 1.1.1 and 1.0.2 are not affected by this issue.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Issue summary: Parsing CMS AuthEnvelopedData message with maliciously
crafted AEAD parameters can trigger a stack buffer overflow.&lt;/p&gt;
&lt;p&gt;Impact summary: A stack buffer overflow may lead to a crash, causing Denial
of Service, or potentially remote code execution.&lt;/p&gt;
&lt;p&gt;When parsing CMS AuthEnvelopedData structures that use AEAD ciphers such as
AES-GCM, the IV (Initialization Vector) encoded in the ASN.1 parameters is
copied into a fixed-size stack buffer without verifying that its length fits
the destination. An attacker can supply a crafted CMS message with an
oversized IV, causing a stack-based out-of-bounds write before any
authentication or tag verification occurs.&lt;/p&gt;
&lt;p&gt;Applications and services that parse untrusted CMS or PKCS#7 content using
AEAD ciphers (e.g., S/MIME AuthEnvelopedData with AES-GCM) are vulnerable.
Because the overflow occurs prior to authentication, no valid key material
is required to trigger it. While exploitability to remote code execution
depends on platform and toolchain mitigations, the stack-based write
primitive represents a severe risk.&lt;/p&gt;
&lt;p&gt;The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this
issue, as the CMS implementation is outside the OpenSSL FIPS module
boundary.&lt;/p&gt;
&lt;p&gt;OpenSSL 3.6, 3.5, 3.4, 3.3 and 3.0 are vulnerable to this issue.&lt;/p&gt;
&lt;p&gt;OpenSSL 1.1.1 and 1.0.2 are not affected by this issue.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-wvhq-3h88-rf6g</guid>
    </item>
    <item>
      <title>ICSA-26-132-05 — ABB AC500 V3 Stack Buffer Overflow in Cryptographic Message Syntax</title>
      <link>https://cve.radiocsirt.org/vuln/icsa-26-132-05</link>
      <description>&lt;p&gt;ABB became aware of vulnerability in the products versions listed as affected in the advisory. An update is available that resolves publicly reported vulnerability.&lt;/p&gt;
&lt;p&gt;An attacker who successfully exploited these vulnerabilities could cause a crash, denial-of-service (DoS), or potentially remote code execution.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;ABB became aware of vulnerability in the products versions listed as affected in the advisory. An update is available that resolves publicly reported vulnerability.&lt;/p&gt;
&lt;p&gt;An attacker who successfully exploited these vulnerabilities could cause a crash, denial-of-service (DoS), or potentially remote code execution.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/icsa-26-132-05</guid>
    </item>
    <item>
      <title>NCSC-2026-0127 — Kwetsbaarheden verholpen in Oracle PeopleSoft</title>
      <link>https://cve.radiocsirt.org/vuln/ncsc-2026-0127</link>
      <description>NCSC-2026-0127</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ncsc-2026-0127</guid>
    </item>
    <item>
      <title>OESA-2026-1310 — openssl security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2026-1310</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS: openssl&lt;/p&gt;
&lt;p&gt;OpenSSL is a robust, commercial-grade, and full-featured toolkit for the Transport Layer Security (TLS) and Secure Sockets Layer (SSL) protocols.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;Issue summary: Parsing CMS AuthEnvelopedData message with maliciously
crafted AEAD parameters can trigger a stack buffer overflow.&lt;/p&gt;
&lt;p&gt;Impact summary: A stack buffer overflow may lead to a crash, causing Denial
of Service, or potentially remote code execution.&lt;/p&gt;
&lt;p&gt;When parsing CMS AuthEnvelopedData structures that use AEAD ciphers such as
AES-GCM, the IV (Initialization Vector) encoded in the ASN.1 parameters is
copied into a fixed-size stack buffer without verifying that its length fits
the destination. An attacker can supply a crafted CMS message with an
oversized IV, causing a stack-based out-of-bounds write before any
authentication or tag verification occurs.&lt;/p&gt;
&lt;p&gt;Applications and services that parse untrusted CMS or PKCS#7 content using
AEAD ciphers (e.g., S/MIME AuthEnvelopedData with AES-GCM) are vulnerable.
Because the overflow occurs prior to authentication, no valid key material
is required to trigger it. While exploitability to remote code execution
depends on platform and toolchain mitigations, the stack-based write
primitive represents a severe risk.&lt;/p&gt;
&lt;p&gt;The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this
issue, as the CMS implementation is outside the OpenSSL FIPS module
boundary.&lt;/p&gt;
&lt;p&gt;OpenSSL 3.6, 3.5, 3.4, 3.3 and 3.0 are vulnerable to this issue.&lt;/p&gt;
&lt;p&gt;OpenSSL 1.1.1 and 1.0.2 are not affected b…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS: openssl&lt;/p&gt;
&lt;p&gt;OpenSSL is a robust, commercial-grade, and full-featured toolkit for the Transport Layer Security (TLS) and Secure Sockets Layer (SSL) protocols.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;Issue summary: Parsing CMS AuthEnvelopedData message with maliciously
crafted AEAD parameters can trigger a stack buffer overflow.&lt;/p&gt;
&lt;p&gt;Impact summary: A stack buffer overflow may lead to a crash, causing Denial
of Service, or potentially remote code execution.&lt;/p&gt;
&lt;p&gt;When parsing CMS AuthEnvelopedData structures that use AEAD ciphers such as
AES-GCM, the IV (Initialization Vector) encoded in the ASN.1 parameters is
copied into a fixed-size stack buffer without verifying that its length fits
the destination. An attacker can supply a crafted CMS message with an
oversized IV, causing a stack-based out-of-bounds write before any
authentication or tag verification occurs.&lt;/p&gt;
&lt;p&gt;Applications and services that parse untrusted CMS or PKCS#7 content using
AEAD ciphers (e.g., S/MIME AuthEnvelopedData with AES-GCM) are vulnerable.
Because the overflow occurs prior to authentication, no valid key material
is required to trigger it. While exploitability to remote code execution
depends on platform and toolchain mitigations, the stack-based write
primitive represents a severe risk.&lt;/p&gt;
&lt;p&gt;The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this
issue, as the CMS implementation is outside the OpenSSL FIPS module
boundary.&lt;/p&gt;
&lt;p&gt;OpenSSL 3.6, 3.5, 3.4, 3.3 and 3.0 are vulnerable to this issue.&lt;/p&gt;
&lt;p&gt;OpenSSL 1.1.1 and 1.0.2 are not affected b…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2026-1310</guid>
    </item>
    <item>
      <title>openSUSE-SU-2026:10237-1 — libopenssl-3-devel-3.5.3-2.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2026:10237-1</link>
      <description>&lt;p&gt;libopenssl-3-devel-3.5.3-2.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;libopenssl-3-devel-3.5.3-2.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2026:10237-1</guid>
    </item>
    <item>
      <title>RHSA-2026:1496 — Red Hat Security Advisory: openssl security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:1496</link>
      <description>&lt;p&gt;openssl: OpenSSL: Arbitrary code execution or denial of service through crafted PKCS#12 file openssl: OpenSSL: Remote code execution or Denial of Service via oversized Initialization Vector in CMS parsing openssl: OpenSSL: Arbitrary code execution due to out-of-bounds write in PKCS#12 processing&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;openssl: OpenSSL: Arbitrary code execution or denial of service through crafted PKCS#12 file openssl: OpenSSL: Remote code execution or Denial of Service via oversized Initialization Vector in CMS parsing openssl: OpenSSL: Arbitrary code execution due to out-of-bounds write in PKCS#12 processing&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:1496</guid>
    </item>
    <item>
      <title>SSA-434797 — SSA-434797: Buffer Overflow Vulnerability in OpenSSL affecting Siemens Products</title>
      <link>https://cve.radiocsirt.org/vuln/ssa-434797</link>
      <description>&lt;p&gt;OpenSSL has published a stack based buffer overflow vulnerability that allows a remote attacker to cause a denial of service (DoS) or potentially allow for remote code execution.&lt;/p&gt;
&lt;p&gt;Siemens has released new versions for several affected products and recommends to update to the latest versions. Siemens is preparing further fix versions and recommends specific countermeasures for products where fixes are not, or not yet available.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;OpenSSL has published a stack based buffer overflow vulnerability that allows a remote attacker to cause a denial of service (DoS) or potentially allow for remote code execution.&lt;/p&gt;
&lt;p&gt;Siemens has released new versions for several affected products and recommends to update to the latest versions. Siemens is preparing further fix versions and recommends specific countermeasures for products where fixes are not, or not yet available.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ssa-434797</guid>
    </item>
    <item>
      <title>SUSE-SU-2026:0311-1 — Security update for openssl-3</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2026:0311-1</link>
      <description>&lt;p&gt;Security update for openssl-3&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for openssl-3&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2026:0311-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2025-15467</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-15467</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: nodejs, Ubuntu:Pro:18.04:LTS: nodejs, Ubuntu:22.04:LTS: openssl, Ubuntu:Pro:22.04:LTS: nodejs, Ubuntu:Pro:FIPS-preview:22.04:LTS: openssl, Ubuntu:Pro:FIPS-preview:22.04:LTS: openssl-fips, Ubuntu:Pro:FIPS-updates:22.04:LTS: openssl, Ubuntu:Pro:FIPS-updates:22.04:LTS: openssl-fips, Ubuntu:24.04:LTS: edk2, Ubuntu:24.04:LTS: openssl and 6 more&lt;/p&gt;
&lt;p&gt;Issue summary: Parsing CMS AuthEnvelopedData or EnvelopedData message with maliciously crafted AEAD parameters can trigger a stack buffer overflow. Impact summary: A stack buffer overflow may lead to a crash, causing Denial of Service, or potentially remote code execution. When parsing CMS (Auth)EnvelopedData structures that use AEAD ciphers such as AES-GCM, the IV (Initialization Vector) encoded in the ASN.1 parameters is copied into a fixed-size stack buffer without verifying that its length fits the destination. An attacker can supply a crafted CMS message with an oversized IV, causing a stack-based out-of-bounds write before any authentication or tag verification occurs. Applications and services that parse untrusted CMS or PKCS#7 content using AEAD ciphers (e.g., S/MIME (Auth)EnvelopedData with AES-GCM) are vulnerable. Because the overflow occurs prior to authentication, no valid key material is required to trigger it. While exploitability to remote code execution depends on platform and toolchain mitigations, the stack-based write primitive represents a severe risk. The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the CMS implementation is outside the OpenSSL FIPS module boundary. OpenSSL 3.6, 3.5, 3.4, 3.3 and 3.0 are vulnerable to this issue. OpenSSL 1.1.1 and 1.0.2 are not affected by this issue. Impact summary: A stack buffer overflow may lead to a crash, causing Denial of Service, or potentially remote code execution. When parsing…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: nodejs, Ubuntu:Pro:18.04:LTS: nodejs, Ubuntu:22.04:LTS: openssl, Ubuntu:Pro:22.04:LTS: nodejs, Ubuntu:Pro:FIPS-preview:22.04:LTS: openssl, Ubuntu:Pro:FIPS-preview:22.04:LTS: openssl-fips, Ubuntu:Pro:FIPS-updates:22.04:LTS: openssl, Ubuntu:Pro:FIPS-updates:22.04:LTS: openssl-fips, Ubuntu:24.04:LTS: edk2, Ubuntu:24.04:LTS: openssl and 6 more&lt;/p&gt;
&lt;p&gt;Issue summary: Parsing CMS AuthEnvelopedData or EnvelopedData message with maliciously crafted AEAD parameters can trigger a stack buffer overflow. Impact summary: A stack buffer overflow may lead to a crash, causing Denial of Service, or potentially remote code execution. When parsing CMS (Auth)EnvelopedData structures that use AEAD ciphers such as AES-GCM, the IV (Initialization Vector) encoded in the ASN.1 parameters is copied into a fixed-size stack buffer without verifying that its length fits the destination. An attacker can supply a crafted CMS message with an oversized IV, causing a stack-based out-of-bounds write before any authentication or tag verification occurs. Applications and services that parse untrusted CMS or PKCS#7 content using AEAD ciphers (e.g., S/MIME (Auth)EnvelopedData with AES-GCM) are vulnerable. Because the overflow occurs prior to authentication, no valid key material is required to trigger it. While exploitability to remote code execution depends on platform and toolchain mitigations, the stack-based write primitive represents a severe risk. The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the CMS implementation is outside the OpenSSL FIPS module boundary. OpenSSL 3.6, 3.5, 3.4, 3.3 and 3.0 are vulnerable to this issue. OpenSSL 1.1.1 and 1.0.2 are not affected by this issue. Impact summary: A stack buffer overflow may lead to a crash, causing Denial of Service, or potentially remote code execution. When parsing…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-15467</guid>
    </item>
    <item>
      <title>VDE-2026-023 — Phoenix Contact: Several products are affected by vulnerabilities found in OpenSSL</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2026-023</link>
      <description>&lt;p&gt;Attacks are possible when installing key files and digitally signed objects. These attacks can only be carried out if these files are uploaded and installed by a logged-in user with high privileges.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Attacks are possible when installing key files and digitally signed objects. These attacks can only be carried out if these files are uploaded and installed by a logged-in user with high privileges.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2026-023</guid>
    </item>
    <item>
      <title>VDE-2026-029 — METTLER TOLEDO: OpenSSL vulnerability in MX and MR balances</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2026-029</link>
      <description>&lt;p&gt;MX/MR firmware V2.0.0 or earlier is affected by the OpenSSL vulnerability CVE-2025-15467.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;MX/MR firmware V2.0.0 or earlier is affected by the OpenSSL vulnerability CVE-2025-15467.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2026-029</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-0234 — OpenSSL: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0234</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in OpenSSL ausnutzen, um beliebigen Programmcode auszuführen, einen Denial-of-Service-Zustand zu verursachen oder vertrauliche Informationen offenzulegen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in OpenSSL ausnutzen, um beliebigen Programmcode auszuführen, einen Denial-of-Service-Zustand zu verursachen oder vertrauliche Informationen offenzulegen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0234</guid>
    </item>
  </channel>
</rss>
